AnkraDocs
Console

Concepts

Floating IPs and firewalls

Public IPv4 addresses you can move between servers in about a second, and per-server stateful firewalls for IPv4 and IPv6.

Floating IPs#

A floating IP is a public IPv4 address held by your account and forwarded 1:1, inbound and outbound, to a server. Moving it to another server takes effect within about a second, which makes it the simplest way to fail a service over or to keep an address across a rebuild.

bash
ankra-cloud floating-ips allocate --zone de-fsn1 --server <server-id> --wait
ankra-cloud floating-ips assign <floating-ip-id> --server <other-server-id> --wait
ankra-cloud floating-ips release <floating-ip-id> --wait

A floating IP's target says where it forwards:

  • public (the default): the server's public interface.
  • private:<network_id>: the server's interface on that private network, which must be attached to a router with NAT enabled. The address then enters and leaves through that NAT gateway, so an IPv6-only server can still own a public IPv4.

While a floating IP forwards to a private interface, turning off that router's NAT, detaching the network from the router or detaching the server from the network answers 409; unassign the floating IP first.

Allocating with a server_id checks the target first and allocates and assigns in one step, so a refused assignment keeps no address. A floating IP costs €4.00 a month, billed per hour from allocation to release. The default quota is 5 per account.

Firewalls#

Every server has one stateful firewall, applied on the host in front of all its interfaces. Changes apply within seconds, also to running servers.

json
{
  "enabled": true,
  "default_inbound": "drop",
  "default_outbound": "accept",
  "rules": [
    { "direction": "inbound", "action": "accept", "protocol": "tcp", "port_start": 443, "port_end": 443, "comment": "https" },
    { "direction": "inbound", "action": "accept", "protocol": "tcp", "port_start": 22, "port_end": 22, "remote_cidr": "2001:db8:1234::/48", "comment": "ssh from the office" },
    { "direction": "inbound", "action": "accept", "protocol": "icmp" }
  ]
}
  • Rules apply in order and the first match decides; otherwise the direction's default applies.
  • Established and related traffic is always allowed, so replies to outbound connections come back.
  • protocol is tcp, udp, icmp or empty for any. Ports need tcp or udp; 0 means any port.
  • remote_cidr is an IPv4 or IPv6 address or CIDR, or empty for any.

Replace the whole firewall with PUT /v1/servers/{id}/firewall (or ankra-cloud firewall set <server-id> --file firewall.json); read it with GET /v1/servers/{id}/firewall.

Independently of your rules, every interface may only send from its own MAC and IP addresses (anti-spoofing), and ICMPv6 neighbour discovery and packet-too-big always pass. The metadata service is not affected by the firewall.